ZeroHour

CVE-2017-5456

PoC
CVSS 3.0
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.

Vendors
redhatmozilla
Products
enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation, firefox
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.